We've just published a new report on a Widespread Credential Harvesting Campaign.
Moving forward, all our CTI updates will come from our main account @bridewellsec, so give us a follow to keep up with our latest updates.
#ransomware#threatintelligence
Joshua Penny, our Senior Threat Intelligence Analyst has analysed a widespread credential harvesting campaign. The threat actors are utilising the Dadsec platform to conduct widespread phishing of global organisations to steal Microsoft 365 credentials.
The threat actors are
We've just published a new report on an information stealer known as "Easy Stealer".
For more info, head over to our main account @bridewellsec. (All future CTI updates will be shared from there so give us a follow!)
#infostealer#threatintelligence
Bridewell CTI has identified infrastructure associated with a new information stealer called “Easy Stealer”.
Easy Stealer is currently up for sale and under active development. Found out more in our full report: bridewell.com/insights/blogs…#infostealer#ThreatIntelligence
We've just published a new report on a major Ransomware-as-a-Service player, ShadowSyndicate.
Moving forward, all our CTI updates will come from our main account @bridewellsec, so give us a follow to keep up with our latest updates.
#ransomware#threatintelligence
ShadowSyndicate is a new Ransomware-as-a-Service player who's having a major impact on the global stage.
We've teamed up with Group-IB and Michael Koczwara to publish a full report on the group: bridewell.com/insights/blogs…#ransomware#threatintelligence
📧 Stay up to date with Bridewell's CTI reports by receiving them directly in your inbox. Sign up here: lnkd.in/eh9DYkRM
In case you missed it 👇 💭
➡ Bridewell and Group-IB expose the APT’s unknown infrastructure - bit.ly/41NHX2S
➡ Hunting for Ursnif - bit.ly/44RksbZ#CTI#Updates
When cybersecurity researchers work together, they make the world safer🤝 Group-IB and @bridewellsec are proud to share the joint blog post about previously unknown infrastructure belonging to #APT#SideWinder:
bit.ly/3MxVjvI
When cybersecurity researchers work together, they make the world safer🤝 Group-IB and @bridewellsec are proud to share the joint blog post about previously unknown infrastructure belonging to #APT#SideWinder:
bit.ly/3MxVjvI
👉SideWinder’s servers can be detected using several hunting rules
👉Group-IB and Bridewell detected 55 previously unknown IP addresses that SideWinder could use in future attacks.
Bridewell and Group-IB expose the APT’s unknown infrastructure.
In our latest report our Bridewell CTI team and the @GroupIB Research Team detail key findings into the APT group ‘SideWinder’.
Read the full report here: insights.bridewell.com/the-distinctiv…
Bridewell CTI track down Ursnif, aka Gozi malware, the ex-banking trojan facilitating ransomware operations such as Royal. The Bridewell team describes recent campaigns involving the malware and how they underwent the hunt for its C2 infrastructure, including an analysis of their findings.
The report can be found here👉bit.ly/42pcDbM#Ursnif#Gozi#Royal#Ransomware
LIDSHOT has two primary functions: system enumeration and downloading and executing shellcode from the C2.
LIDSHOT sends the following information to its C2:
Computer Name
Product name
IP address
Process List
Mandiant’s UNC2970 conduct recruitment themed spear-phishing campaigns, recently delivering a trojanised version of TightVNC (LIDSHIFT) to victims.
LIDSHIFT reflectively loads an encrypted .dll into memory; a trojanised Notepad++ plugin, called LIDSHOT.
🚨⚠️Potential #Nukesped/#LIDSHOT#malware🔍 uploaded from South Korea. Only 2 detections on VT:
🔗ddb240cf6125f320330fcba78c3ac219c934ca6c8878bb659a84b7d78ae39ba3 📁FWDataViz.dll
LIDSHOT's dual threat:
1️⃣ System enumeration🕵️♂️
2️⃣ Downloading & executing shellcode from C2 🌐
10K Followers 644 FollowingA leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime since 2003
123K Followers 8K FollowingDepartment of Cyber WAR.
Member of the Counter Spider Collective.
Wielder of AI to defend in Cyber Space.
Ralph Vibe Specialist.
VibeOps Operator!
4K Followers 2K FollowingBridewell is a leading cyber security company that specialises in protecting CNI organisations and those who want the highest standard of cyber security.
14K Followers 1K FollowingAuthor/Operator of @ScumBots. Blue Team by day, Blue Team by night. Opinions, typos, and bad grammar do not represent my employer. He/Him
5K Followers 98 FollowingCreator of Debloat and https://t.co/tIYqmw6pxt
Support: https://t.co/l9kCPRoD2y
Join the Debloat/CertGraveyard discord: https://t.co/ZcWIqa6ZA9
4K Followers 146 FollowingA #SOCplatform boosted by #AI and #threatintelligence, combining #SIEM, #SOAR, #Automation in a single solution. Used by End-users, MSSP and APIs
127K Followers 81 FollowingServing as the Director of the National Counterintelligence and Security Center under the leadership of @POTUS and @DNIGabbard.
286K Followers 5K FollowingCloudflare is the world’s leading #ConnectivityCloud, and we have our eyes set on an ambitious goal — to help build a #BetterInternet.
714K Followers 470 FollowingWhat you want to know about tech. A section of @thisisinsider. Follow us on Facebook, Instagram, and YouTube. Visit our homepage for the day's top stories.
566K Followers 745 FollowingWelcome to the new way to cloud.
Questions? ➡️ https://t.co/BFKBu3tEmS
For do-ers & makers ➡️ @GoogleCloudTech
Watch #GoogleCloudNext on demand ⬇️
1.3M Followers 2K FollowingFollow along for how-tos, demos, product news, and more.
For company updates, check out @GoogleCloud.
Watch #GoogleCloudNext on demand ⬇️
4.9M Followers 4 FollowingOpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6LgzPA
72K Followers 139 FollowingHave questions, or building something cool with Cloudflare's Developer products? We're here to help. For help with your account please try @CloudflareHelp
1.1M Followers 0 FollowingNational Security Agency/Central Security Service official account, home to America's codemakers and codebreakers. Likes, retweets, and follows ≠ endorsement.
291K Followers 145 FollowingThe Defense Intelligence Agency is first in all-source military intelligence in support of warfighters, defense planners, & policymakers.
298K Followers 73 FollowingPart of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
807K Followers 323 FollowingTogether with the AI community, we are pushing the boundaries of what’s possible through open science to create a more connected world.
186K Followers 1K FollowingThe National Cybersecurity Alliance is a nonprofit that empowers people to use technology safely & securely. Co-leads Cybersecurity Awareness Month
250K Followers 2K FollowingThe world's leading publication for data science and artificial intelligence professionals.
Submit an Article ✍️ https://t.co/57pIMegK1o
1.4M Followers 577 FollowingCelebrating the people and stories that matter to our great city.
🔊 Listen to BBC Radio London @BBCSounds ➡️ https://t.co/otcogG6Haz
👇 Tap the link for more
417K Followers 50 FollowingTypeScript is a language for application-scale JavaScript development. It's a typed superset of JavaScript that compiles to plain JavaScript.